August 29, 2026

ReCAAP ISC: Intelligence Source Guide

0

ReCAAP ISC is the treaty-based information sharing centre for piracy and armed robbery against ships in Asia, run from Singapore through government focal points. It is the only maritime incident source that classifies every incident by a published severity scheme – and the only one whose most imp…

recaap-isc-intelligence-source-guide

ReCAAP ISC is the treaty-based information sharing centre for piracy and armed robbery against ships in Asia, run from Singapore through government focal points. It is the only maritime incident source that classifies every incident by a published severity scheme – and the only one whose most important gap is which states never joined.

At a glance

Source ReCAAP ISC
Category Conflict, Crime & Human Security › Organised Crime, Gangs & Piracy
Homepage https://www.recaap.org/
Format HTML
Access Open — no account required
Disciplines Maritime Intelligence, Open Source Intelligence
Mission domains Maritime Piracy

Asia regional piracy incident sharing. — as catalogued in the platform’s own source registry.

The Regional Cooperation Agreement on Combating Piracy and Armed Robbery against Ships in Asia is a multilateral agreement concluded in Tokyo in 2004 and in force since September 2006. It established an Information Sharing Centre in Singapore that is the operational output of the treaty. The mechanism works through designated national focal points: each contracting party nominates an agency – typically a coast guard, maritime police or maritime administration – which reports incidents in its waters to the ISC and receives alerts and requests from it. The ISC verifies, classifies and disseminates. Its public products are a weekly report, monthly and quarterly reports, an annual report, and immediate incident alerts, all published as documents on its website. Each incident entry carries a date and time, a position, a location description, the vessel's name, type, flag and IMO number in most cases, the vessel's status, a narrative account, the number and armament of perpetrators, what was taken, whether crew were harmed, and the ISC's own classification of the incident. There is no public API and no dataset download; the products are documents designed to be read by mariners, ship operators and agencies.

Two things make it analytically distinct from every other maritime incident source. The first is legal precision. ReCAAP consistently distinguishes piracy, which under the law of the sea occurs outside any state's territorial sea, from armed robbery against ships, which occurs within it – and it labels each incident accordingly. Nobody else does this systematically, and the distinction determines which state may act, which navy may intervene, and how an incident should be described in any legal or policy document. The second is the severity classification. ReCAAP assigns incidents to categories based on the violence involved – the number of perpetrators, whether they were armed and with what, whether crew were harmed or taken – and on the economic consequence, which produces a consistent, published, reproducible severity ordering across years and locations. That converts a pile of narratives into a comparable series, and it is the single most useful structured attribute in maritime crime open source. For any Asian maritime question, this is the reference product; for comparative work elsewhere, its classification scheme is the model worth borrowing.

Who publishes it, and why that matters

The ISC is an intergovernmental body funded by its contracting parties and hosted in Singapore. That gives it durability, direct access to state reporting, and a mandate to receive information that industry bodies must ask for. It also gives it the constraints of any organisation reporting on its members. The ISC is diplomatic in tone, careful about attributing failure to a coastal state, and dependent on focal points to pass on incidents that reflect badly on their own waters. The critical structural fact is membership. The agreement has more than twenty contracting parties, including states from outside Asia, but two of the most incident-dense archipelagic states in the region are not among them and have historically declined to accede. They cooperate to varying degrees through other channels, but they are not focal points, which means reporting from their waters reaches the ISC through masters, industry bodies and neighbours rather than through the treaty mechanism. Any assessment of Southeast Asian maritime crime that does not account for this is describing the reporting architecture rather than the sea. Read the ISC as accurate, legally careful and institutionally constrained: it will not overstate, and it cannot report what a non-member state does not surface.

Provenance is the first question to ask of any dataset and the one most often skipped. Who collects it, what their incentive is, whether they publish a methodology, and whether they correct the record when they get something wrong all bear directly on how much weight a finding drawn from it can carry.

What a record actually contains

The fields you will be working with, what each one means, and whether it is something you can pivot on. Read the meanings carefully — more analysis is wrecked by misreading a field than by failing to find one, and a field that looks like an observation is often an inference.

Field Type What it means Pivot value
incident reference string The ISC's identifier for an incident, used consistently across the weekly, monthly and annual products. It is the key that lets you track how an incident's details were revised as more information arrived. Cross-referencing the same incident between ReCAAP products and against the industry and official records.
date and time timestamp When the incident occurred, usually with a local time reference and often to the hour, which is finer than most maritime incident sources achieve. Correlation with AIS position history, tidal and light conditions, and traffic patterns at the hour of the attack.
position string Latitude and longitude of the incident, generally to a level of precision that reflects the ship's own reported position rather than a rounded estimate. Geospatial correlation with traffic separation schemes, anchorages, territorial sea boundaries – which is what determines the legal characterisation.
location description string Named waters: the Singapore Strait eastbound lane, a specific anchorage, an approach to a named port. Frequently more analytically useful than the coordinates because it identifies the operating environment and the responsible authority. Port and anchorage entities; grouping by jurisdiction and by governance regime.
vessel name, type, flag, IMO number string Ship identity, usually complete including the IMO number. This is a material advantage over sources that routinely withhold identity, and it is what makes ownership and repeat-victimisation analysis possible in this region. Vessel registries, ownership and management chains, port state control history, AIS identity – always keyed on the IMO number.
vessel status enum Whether the ship was underway, anchored, berthed or drifting when boarded. Together with location this determines both the legal category and the practical nature of the threat. Separating anchorage theft from underway attack; correlating with port congestion and waiting time.
incident classification enum The ISC's severity category, assigned from the violence factor – number of perpetrators, weapons carried, treatment of crew – and the economic loss factor. Also distinguishes attempted incidents and petty theft from significant attacks. Severity trend analysis; the single most reusable structured attribute in open-source maritime crime data.
legal category enum Whether the incident constitutes piracy under the law of the sea or armed robbery against ships within territorial waters. Determined by where it occurred, and stated explicitly – which almost no other source does. Jurisdiction analysis, the lawfulness of any intervention, and correct characterisation in legal and policy products.
perpetrator details string Number of persons, whether armed and with what – knives, machetes, guns – and how they arrived and boarded. Reported more consistently here than in most sources because focal points follow up. Modus operandi profiling, linkage of incidents to a consistent group, and capability assessment.
crew consequences string Whether crew were threatened, assaulted, tied up, taken hostage or abducted, and how many. Recorded systematically and used as an input to the severity classification. Seafarer welfare analysis and the bridge into kidnap-for-ransom work where crew abduction is the pattern.
property taken string What the perpetrators removed – engine spares, scrap metal, ship's stores, crew belongings, cargo, or in the most serious cases the cargo itself or the vessel. The economic loss factor in the classification derives from this. Criminal economy analysis: what is being stolen indicates who the buyer is and where the onward market sits.
response and follow-up string What the ship did, whether the ISC issued an alert, whether an authority was notified and responded, and any subsequent arrest or recovery. This closes the loop that most incident records leave open. Coastal state capability and willingness assessment; enforcement effectiveness by jurisdiction.

Coverage — and what is not in it

Asia, from the waters of South Asia across Southeast Asia to East Asia, defined by the agreement's reporting area rather than by any continental definition. In practice the reporting is dominated by the Singapore Strait and its approaches, the Indonesian archipelago and its anchorages, the Philippine and Sulu-Celebes waters, the Bay of Bengal anchorages off Bangladesh, Vietnamese and Malaysian port approaches, and the South China Sea shipping lanes. The record runs continuously from the centre's establishment in the mid-2000s, giving close to two decades of consistently classified incidents – which is the longest run of severity-classified maritime incident data anywhere. Cadence is genuinely useful: immediate alerts for significant incidents, a weekly report that is the working document for anyone monitoring the region, and monthly, quarterly and annual consolidations that revise and contextualise. Coverage does not extend to the Gulf of Guinea, the Horn of Africa, the Americas or European waters, and the ISC is explicit about this – it will occasionally note incidents elsewhere for context but it does not purport to record them. Within its area, coverage is strongest where a contracting party's focal point is engaged and weakest in the waters of states that are not parties to the agreement, which is a geographic bias that maps almost exactly onto the region's highest-incident archipelagic waters.

Known blind spots

Absence of evidence here is not evidence of absence. These are the conditions under which ReCAAP ISC will not show you something that is nevertheless real:

  • Non-member states are the structural gap. Two of the most incident-dense archipelagic states in Southeast Asia are not contracting parties, so incidents in their waters reach the ISC by indirect routes if at all, and any regional total under-represents exactly the waters that matter most.
  • Focal points are government agencies reporting on their own jurisdictions, which creates a quiet incentive against surfacing incidents that reflect poorly on enforcement, particularly in ports and anchorages under a single authority's control.
  • The reporting area is Asia. A network operating between Asian and non-Asian waters is visible only on the Asian leg, and analysts working transnational cases will need a separate source for the rest of the chain.
  • Local and small craft are largely absent. Fishing vessels, coastal traders, tugs and barges suffer significant maritime crime and rarely generate a report through a mechanism designed around commercial shipping.
  • Crime that does not involve boarding a vessel is out of scope – smuggling, trafficking by sea, illegal fishing, and the corruption that enables all of them – even though the same networks and waters are involved.
  • Abductions that begin ashore, in a port or from a fishing community, may not enter the record even when the same perpetrators are responsible for attacks at sea.
  • There is no negative reporting and no traffic denominator, so a quiet quarter cannot be distinguished from a quarter in which focal points were slow, and incident counts move with congestion and trade volume.
  • Products are documents rather than data. There is no API and no export, so anything structured you want must be extracted from PDFs, which introduces transcription error and a real ongoing labour cost.
  • Diplomatic constraint shapes the language. The ISC will state facts and will not usually state the conclusion that a coastal state is failing, so the most consequential judgement in a regional assessment is one you must make yourself from the evidence it publishes.

Write the blind spot into the product. A statement that something “was not observed in ReCAAP ISC” is defensible; a statement that it “did not happen” is not, and the difference is what survives cross-examination.

Access, licensing and what you may do with it

Access model: Open — no account required

The website publishes weekly, monthly, quarterly and annual reports and incident alerts, free and without registration, as documents. There is no API, no bulk download and no structured export. Practical collection has two modes. For current awareness, take the weekly report as it appears – it is compact, consistently formatted, and reading it takes a few minutes, which is a better use of an analyst than any pipeline you could build. For analysis, extract the incident tables from the periodic reports into your own store, and expect to invest real effort in parsing and in quality control because document layouts change between years. The annual reports are the citable products and they contain revised figures, so for any published claim use the annual rather than the sum of the weeklies. If you need bulk historical data for research, approach the centre directly rather than scraping; an intergovernmental body with a stated information-sharing mandate is a reasonable candidate for a research request, and the answer will be more reliable than anything a parser gives you.

Licence

The ISC publishes its reports for public benefit under an information-sharing mandate, and the material is freely readable. That does not make it public domain: assume the documents are the centre's copyright and that redistribution beyond citation requires permission. The safe posture is to cite specific reports by title and date, quote briefly, reproduce individual incident details with attribution where necessary for a case, and derive your own statistics rather than republishing the tables. Because the terms are not always prominently stated, do not infer a permissive licence from their absence – ask. If you need incident rows you can redistribute without any encumbrance, the official government anti-shipping message feed is the answer, and the correct architecture is to build on that and use ReCAAP for the severity classification, the legal characterisation and the follow-up detail that the other sources lack.

Rate limits and fair use

No API means no limits and no excuse for aggressive collection. Fetch the weekly report once a week and the periodic reports when they appear; there is nothing else to poll. Do not crawl the archive repeatedly, identify your collector with a contact address if you automate document retrieval, and cache everything locally. A useful discipline here is that the human reading cadence and the machine collection cadence should be the same: if an analyst would not read it more than once a week, your collector should not fetch it more than once a week either.

Licensing changes, and it changes without warning. A dataset that was free for research this year may not be free for commercial or evidential use next year. Confirm the current terms before you build a dependency on it, and record the terms you relied on alongside the data — the licence in force at the time of collection is part of the provenance.

Collecting it

How ReCAAP ISC is actually pulled, in the order you would set it up. Prefer the bulk or export interface over per-item lookups wherever one exists: it is kinder to the publisher, faster for you, and gives a reproducible snapshot rather than a series of point-in-time answers you cannot reconstruct later.

Method Format Cadence Notes
Weekly report HTML weekly The working document for regional monitoring, listing incidents for the week with position, vessel, classification and narrative. Short enough that an analyst should read it rather than parse it.
Incident alerts HTML as issued Immediate notifications for significant incidents, particularly crew abduction and attacks in specific waters. This is the fastest ReCAAP product and the one to route to an operational watch.
Monthly and quarterly reports HTML monthly and quarterly Consolidated tables with classification breakdowns and commentary on trends. The right granularity for a rolling regional assessment and for spotting where figures have been revised.
Annual report HTML annual The citable statistical product with the year's revised figures, multi-year comparisons and thematic analysis. Use this rather than a sum of weeklies for anything you publish.
Special and thematic reports HTML irregular Focused studies on a specific phenomenon or water – crew abduction in particular waters, incident patterns in a strait. These carry the ISC's most substantive analysis and are worth reading in full.
Analyst extraction to structured store CSV per reporting period Transcribe incident tables into your own schema with the ISC classification preserved verbatim. Budget for layout changes between years and for a verification pass; this is the only way to get a usable series and it is manual work.

Ingesting it into the platform

Every step below is idempotent and cursor-based: interrupt one and it resumes from where it stopped rather than duplicating rows or losing progress. Collection is recorded per source, so a feed that quietly stops publishing shows up as a stale timestamp instead of silently thinning your coverage.

  1. Register as a document source with manual extraction — Record it in sources.php with an explicit note that collection is document-based and analyst-verified, so nothing derived from it carries the automatic confidence of a structured feed.
  2. Preserve the ISC classification verbatim — Store the severity category and the legal category exactly as published, in their own fields, before any mapping. These are the source's most valuable outputs and any normalisation must be reversible and auditable.
  3. Resolve vessels on IMO number — Because identity is usually complete here, resolve each victim vessel to a persistent entity via registry lookup at ingest. This is the region where repeat-victimisation analysis is actually possible, and it depends on doing this consistently.
  4. Deduplicate against the official and industry records — Run correlate.php against the government anti-shipping feed and the industry reporting centre listing. The same incident appears in all three with different references, positions and sometimes classifications, and the divergence should be preserved rather than resolved.
  5. Derive the jurisdictional context — For each incident, determine from the position whether it lies within a territorial sea, an archipelagic water, or beyond, and store that alongside the ISC's own legal category. Where your derivation disagrees with the published category, flag it for analyst review rather than overriding either.
  6. Emit vessel and location data points — Each incident yields a dp_vessel with full identity and a dp_location with the position and named waters. Crew consequence details feed the kidnap and welfare views rather than sitting inert in a narrative field.
  7. Track revisions across products — When the same incident reference appears in a later report with changed details, keep both versions with their publication dates. Revision history is evidence about how much was initially known, which matters when you are assessing the reliability of early reporting elsewhere.
  8. Publish against traffic and jurisdiction — Surface incidents in ais.php and theater.php normalised by traffic and grouped by responsible authority, so that the analytically important question – which jurisdiction is failing – is visible rather than buried in a regional total.

Registered sources and their last-collected state are listed in sources.php, and the scheduled chain that keeps them current is in automation.php.

How it is wrong, and how to tell

Every dataset is wrong in characteristic ways. Knowing which ways is the difference between using a source and being used by one, and it is the part of source evaluation most often skipped because it is the part that takes work.

This is the most carefully produced open maritime incident record available. Incidents are verified through official channels rather than taken on a single report, vessel identity is usually complete, positions are precise, the narrative detail on perpetrators and crew treatment is systematically collected, and the classification is applied consistently enough to support multi-year comparison. Where other sources give you an incident, ReCAAP gives you an incident with a severity, a legal category and a follow-up. The quality limit is not accuracy but coverage, and it is structural rather than accidental: the mechanism depends on contracting party focal points, so the record's completeness varies with the political geography of the agreement rather than with the distribution of crime. Judge it by comparing its count for a given water against the industry and official records for the same period. Where ReCAAP has a focal point, its record is usually the most complete and the most detailed of the three. Where it does not, it is frequently the thinnest – and that pattern, once you have measured it for your areas of interest, is more useful than any single figure the report contains.

Characteristic false positives

  • Regional totals read as regional crime. Because the highest-incident archipelagic waters belong to states outside the agreement, the aggregate under-represents them systematically, and a year-on-year regional comparison can move because of reporting relationships rather than because of incidents.
  • Severity categories aggregated away. The classification exists precisely so that a petty anchorage theft and an armed hijacking are not the same event, and the most common misuse is to sum them into one incident count for a headline.
  • The legal category ignored. Most incidents in this region are armed robbery within territorial waters rather than piracy in law, and reporting them as piracy misstates jurisdiction and can be picked apart by any maritime lawyer reading your product.
  • Double counting across sources. The same incident exists in the ReCAAP report, the official anti-shipping feed and the industry listing, with different references and slightly different positions, and unioning them without matching inflates counts substantially.
  • Focal point activity read as security change. When a state's reporting improves or lapses, its incident count moves without anything changing on the water, and the record does not annotate this.
  • Early figures treated as final. Weekly reports carry initial accounts that are revised in later products as follow-up arrives, so a claim built on the first report of an incident may be superseded within a month.
  • Attempted incidents merged with successful ones. The record distinguishes them clearly and analysts routinely do not, which inflates apparent risk for exactly the waters where deterrence is working.
  • Diplomatic silence read as absence of a problem. The ISC states facts and generally avoids concluding that a coastal state is failing, so the absence of criticism in the text is not evidence that criticism is unwarranted.

None of these make the source unusable. They make it a source that requires corroboration before an assertion built on it goes into a product, which is true of every source and admitted by few.

Ageing

Three separate clocks run here. Individual incident records are revised: the weekly account is provisional, the monthly and quarterly consolidations add follow-up, and the annual report contains the settled version, so a record's age determines how much you should trust its detail. Regional patterns age within a season – the Singapore Strait's incident rate has repeatedly shifted within months in response to enforcement posture, congestion, monsoon conditions and economic pressure ashore – so an assessment built on incidents more than two quarters old describes an environment that may have changed entirely. And the institutional picture ages slowly but decisively: membership changes, focal point capability improves or degrades, and the meaning of the record changes with it. A stale ReCAAP-derived product looks like a confident severity trend for a strait, drawn from an annual report two years old, presented without a validity date to a client planning a transit next month. Refresh regional assessments quarterly, always cite the annual rather than early figures for published claims, and re-read the membership position before making any statement about regional completeness.

What this source feeds

A source is only worth what it lets you conclude. These are the disciplines that collect through it, the mission domains it serves and the data points it yields — every one is a tag, so you can follow any thread from here into the rest of the library.

Collected by these intelligence disciplines

Serves these mission domains

Yields these data points

How each sector uses ReCAAP ISC

The same dataset is worked very differently depending on who you are, what authority you hold, and what you are ultimately producing. A military analyst is supporting a commander’s decision; a journalist is meeting a publication standard; an NGO caseworker is protecting a person. The records are shared — the constraints, thresholds and outputs are not.

🎖 Military and defence

For navies and coast guards operating in Asian waters, ReCAAP is the shared regional picture that coalition and bilateral partners already use, and its classification scheme gives you a common severity language across jurisdictions with very different domestic reporting practices. Use the underway-versus-anchored split and the perpetrator armament detail to size the response: a strait with repeated boardings by small unarmed groups seeking engine spares requires a different posture from waters where armed groups take crew. The follow-up field is the effectiveness measure – whether an authority responded, and what happened – and tracking it by jurisdiction is a better indicator of regional maritime security capability than any incident total.

🕵 National intelligence

For maritime intelligence, the analytically distinctive product is the severity classification, which lets you say whether an environment is deteriorating in kind rather than merely in count. A rise in low-severity anchorage theft and a rise in armed underway boardings are different phenomena with different drivers, and only this source separates them consistently over two decades. The membership geography is itself an intelligence question: knowing that the record thins in the waters of non-parties tells you where to direct independent collection. Read the special reports closely – they contain the ISC's most substantive analysis and are frequently the earliest structured account of an emerging pattern such as a shift towards crew abduction.

👮 Law enforcement

For maritime law enforcement, the legal category field is the operational one. Whether an incident was piracy on the high seas or armed robbery within a territorial sea determines who has jurisdiction, whether universal jurisdiction is available, and which mutual legal assistance route applies – and this is the only source that states it for every incident. The perpetrator and modus operandi detail supports linkage across incidents and jurisdictions, and the near-complete vessel identity means you can pursue the shipping company for the primary evidence. As with all incident records, this is not evidence itself; it is a locator for the coastal state's investigation file and the ship's own documents.

🔍 Private investigation and corporate security

For maritime security consultancies and insurers advising on Asian trades, this is the source your client's other advisers will be quoting, and the value you add is in reading it properly. Present the severity ladder rather than a count, separate anchorage from underway risk, normalise against traffic and waiting time, and be explicit about the non-member coverage gap when advising on transits through the waters it affects. The vessel identity completeness makes repeat-victimisation analysis genuinely possible here, which is directly actionable: if a client's routing or freeboard or anchoring practice puts them in a repeatedly targeted category, that is a finding they can act on this week.

📰 Journalism and OSINT media

For journalists, ReCAAP is credible, quotable and unusually precise, and the traps are definitional and geographic. Do not call territorial-water armed robbery piracy without saying so; do not present a regional total without noting which major states are outside the mechanism; do not compare a ReCAAP figure directly with an industry figure, since they count differently and verify differently. The strongest stories come from the severity trend rather than the count, from the crew consequences that shipping coverage tends to skip, and from the divergence between what the mechanism records and what individual coastal states acknowledge.

🌍 NGO, humanitarian and human rights

For seafarer welfare and human rights organisations, the crew consequence recording is more systematic here than anywhere else, which makes this the best available basis for advocacy about harm to crews in Asian waters. The pattern by vessel type and flag exposes which seafarers carry the risk, and the perpetrator armament detail supports arguments about the real conditions crews face. Protect the identity of affected crew in anything you publish, aggregate for advocacy, and route live welfare concerns through established seafarer support mechanisms and the shipowner rather than through the incident record. Note the source's commercial-shipping frame: harm to fishers and to people moving by sea in small craft sits largely outside it.

🎓 University and research

For maritime security research, ReCAAP offers something rare – a consistently classified incident series spanning nearly two decades, produced by a single institution under a published methodology. That makes it the best available basis for studying severity dynamics rather than raw counts, and for studying the effect of enforcement interventions in specific waters. The research design must confront two things explicitly: the membership geography, which is a non-random coverage bias correlated with the outcome of interest, and the document-only publication, which means your dataset is a transcription with an error rate you should measure and report. Note also that the licence is not open, so plan replication materials around derived statistics rather than redistributed tables.

Playbook: working ReCAAP ISC end to end

A repeatable sequence from first pull to finished product. Each phase states what you are trying to establish, not merely what to click — the objective is a defensible chain of reasoning, not a completed checklist.

Phase 1 — Establish the membership geography first

Before anything else, determine which states in your area of interest are contracting parties with active focal points and which are not. This single fact determines how to read every number that follows, and it is the caveat that must appear in your product. An analyst who skips it will present a reporting map as a crime map.

Phase 2 — Decide which legal frame your product needs

Establish whether your reader needs piracy in the law-of-the-sea sense, armed robbery within territorial waters, or both combined as attacks on shipping. ReCAAP is the only source that lets you answer precisely, so use that precision rather than collapsing it, and state which frame you used.

Phase 3 — Build the series from annual reports, not weeklies

Take incident tables from the annual reports as your statistical basis, because they contain the revised and settled figures. Use the weeklies for current awareness and for narrative detail, and keep the two roles separate so that a provisional early account never becomes a published number.

Phase 4 — Preserve the classification and build on it

Carry the ISC severity category into your own store verbatim, then derive whatever ladder your product needs on top of it. Never discard the original. The classification is the reason to use this source, and a normalised value with no path back to the published category is a self-inflicted loss.

Phase 5 — Split by vessel status and location type

Separate underway incidents in straits and lanes from anchorage and berth incidents. These are different crimes committed by different people for different reasons, and merging them produces an assessment that is wrong for a transiting master and wrong for a port operator simultaneously.

Phase 6 — Deduplicate across the three regional records

Match ReCAAP incidents against the official anti-shipping feed and the industry listing on date, position proximity and vessel identity – which is unusually feasible here because IMO numbers are usually present. Keep the divergences: where two sources classify the same incident differently, that disagreement is a finding about how each source sees the water.

Phase 7 — Normalise against traffic and waiting time

Obtain transit counts for the straits and occupancy for the anchorages in your area. Incidents per thousand transits and per thousand ship-hours at anchor are the measures that survive scrutiny, and they routinely dissolve apparent surges that were congestion effects.

Phase 8 — Profile repeat victimisation

Resolve victim vessels to IMO numbers and look for hulls, operators, trades and hull types that recur. Because identity completeness is high here, this analysis actually works in this region, and it produces the most directly actionable output a shipping client can receive.

Phase 9 — Read perpetrator detail as capability

Aggregate group size, armament and boarding method by location and period. A shift from four unarmed men with a pole to eight men with firearms is an escalation in capability that will show in this field long before it shows in the incident count, and it is the thing that should trigger a change in your advice.

Phase 10 — Track the response field by jurisdiction

Code every incident for whether an authority was notified, whether it responded, and what followed. Aggregated by responsible authority, this is an enforcement-effectiveness measure that the ISC's own diplomatic language will not state and that your client cannot get anywhere else.

Phase 11 — Cross-read the special reports

Read the thematic and special reports in full rather than mining them for figures. They contain the centre's substantive analysis, they frequently identify an emerging pattern first, and they show you which questions the practitioners closest to the data consider unresolved.

Phase 12 — Publish with membership, denominator and validity date

State the coverage gap created by non-party waters, the traffic normalisation, the severity breakdown and the incident window on the face of the product. Maritime assessments circulate long after they are written, and these four statements are what stop yours being misused a year from now.

The platform ships this as a step-checked workflow in playbooks.php, so progress is recorded against a case rather than held in someone’s head.

What to pair it with

No single source carries a finding. These are the datasets that corroborate, extend or contradict this one — and a source that contradicts is worth more than one that agrees, because it is the only thing that will tell you when you are wrong.

Source Relationship What it adds
NGA Anti-Shipping Activity Messages corroborates The machine-readable, public-domain official incident feed. Weaker on severity and legal category, far better for automated pipelines and unencumbered redistribution.
IMB Piracy Reporting Centre corroborates The industry-side record collected directly from ships, using a broader operational definition. The comparison with ReCAAP for the same waters is the standard test of reporting completeness in Asia.
IMO GISIS corroborates State-reported incident data through the IMO, providing a third and differently biased reading of the same events.
IMO legal framework prerequisite The definitions that underpin the piracy versus armed robbery distinction and the code of practice for investigation. Read this before you use the legal category field in anything consequential.
Equasis prerequisite Free ship particulars, ownership and management data. With IMO numbers usually present in ReCAAP records, this is the immediate and reliable pivot to the company behind the ship.
AIS vessel tracking extends Traffic density for the denominator and individual position history for incident context – whether the ship was slow-steaming, waiting or drifting when attacked.
BIMCO extends Industry guidance and best management practice for the affected regions, which is the countermeasure vocabulary any client-facing recommendation should map onto.
UNODC extends Analysis of the wider maritime crime economy in the region – trafficking, illegal fishing and the onward markets for stolen ship stores and cargo – which the incident record does not cover.

Legal, ethical and operational constraints

The distinctive legal contribution of this source is also its principal legal hazard: it states, per incident, whether the act was piracy or armed robbery against ships, and that determination governs jurisdiction, the lawfulness of intervention by a third-state warship, and the applicable prosecuting authority. Use the field, and use it accurately; do not aggregate the two categories under the word piracy in any product with legal or policy consequence. On the data itself, assume the reports are copyrighted and that redistribution beyond citation needs permission – free to read is not open. On personal data, incident narratives describe crew who were threatened, assaulted, tied up or abducted, and although vessel and crew details are published, republishing identifying details of individual seafarers in a commercial product engages data protection obligations in most jurisdictions and can cause real harm to people with limited recourse. Finally, be careful with attribution of state failure: the ISC's diplomatic register is deliberate, and an assessment that a coastal state is complicit or negligent is your conclusion, drawn from published facts, and should be presented as such with its evidential basis rather than as something the centre said.

Operational security

Downloading public reports from an intergovernmental centre is low-exposure activity, and the ordinary reading pattern reveals little. Two considerations apply. Automated document retrieval creates a visible pattern at a body whose membership includes states with an interest in who is studying their waters; keep collection at human cadence and identified. More significantly, direct correspondence with the ISC or with a national focal point about a specific vessel, incident or company discloses your client's interest into a government-to-government channel, where it may reach the maritime authority of a state that is itself a subject of your enquiry. For sensitive commercial or investigative work, take what you need from the published products, and route any enquiry that must be made through a channel your client has explicitly agreed to and understands the reach of.

Two rules that hold regardless of jurisdiction. Collection that is lawful is not automatically proportionate, and a dataset assembled for one purpose does not carry consent for another. Where the records concern identifiable people, the question is not only whether you may hold the data but whether holding it serves the purpose you are accountable for.

Is it earning its place?

Sources accumulate. Feeds get added during an incident and are never reviewed again, and a decade later the pipeline is carrying dead weight that nobody dares remove. These are the measures that show whether ReCAAP ISC is contributing anything, and they are worth baselining now so the answer is available later.

  • Ratio of ReCAAP incident counts to the official and industry records for the same waters and period, tracked separately for contracting-party and non-party waters as your working completeness measure.
  • Proportion of incidents with a complete vessel identity including IMO number, which in this source should be high and which bounds all ownership and repeat-victimisation analysis.
  • Revision rate: how often an incident's details change between the weekly report and the annual, as a measure of how much weight early reporting can carry in your process.
  • Severity distribution over time for each water of interest, monitored for shifts in composition rather than in total, since composition is what changes advice.
  • Response rate by jurisdiction – the share of incidents where an authority was notified and responded – as an enforcement-effectiveness indicator you can defend.
  • Transcription error rate in your extracted series, measured by re-checking a sample against the published documents, because document-derived data always has one and yours is unmeasured until you measure it.
  • Analyst time per reporting period to extract and verify the incident tables, which determines whether this pipeline is sustainable at your coverage ambition.
  • Share of your regional products that stated the non-party coverage gap explicitly, as a direct quality-control count.

Beware of volume. Indicator counts rise easily and say almost nothing. Unique contribution — findings this source produced that no other source in your stack would have — is the measure that matters, and it is usually far lower than anyone expects.

Tradecraft notes

The distinctions that separate a competent analyst from a fast one:

  • Membership is the first fact, not a footnote. Which states are contracting parties determines what the record can see, and the largest gaps sit in the highest-incident waters. Say this in every regional product.
  • Never merge the severity categories. The classification is the reason this source exists and the reason it is better than its alternatives; a combined incident count throws away its entire comparative advantage.
  • Use the legal category and use it precisely. It is the only place in open source where piracy and armed robbery against ships are distinguished per incident, and it determines who may lawfully act.
  • Cite the annual, monitor the weekly. Early accounts are provisional and get revised; publishing a figure from a weekly report is how you end up correcting a client deliverable.
  • IMO numbers make this region analytically different. Because identity is usually complete, repeat-victimisation and fleet-exposure analysis actually work here – do that work, because it is the output a shipping client can act on.
  • Perpetrator armament is a leading indicator. Capability escalation shows in the group size and weapons detail before it shows in incident counts, and this is the field to monitor if you are advising on transit risk.
  • Deduplicate across the three regional records before counting anything, and preserve the disagreements between them rather than resolving them – the disagreement tells you how each source sees the water.
  • Read the diplomatic register. The ISC states facts and avoids conclusions about state failure, so the absence of criticism is not an absence of grounds; drawing that conclusion is your job and it must carry your evidence.
  • Normalise by transits and anchorage hours. In the world's busiest straits, incident counts follow traffic, and an unnormalised trend will have you briefing congestion as escalation.

Questions analysts actually ask

Is there an API or a downloadable dataset?

No. The ISC publishes weekly, monthly, quarterly and annual reports as documents. Anything structured has to be extracted by you, with a transcription error rate you should measure. If you need machine-readable incident rows, build on the official government feed and use ReCAAP for severity, legal category and follow-up.

Why do ReCAAP figures differ from the industry reporting centre's?

Different reporting routes, different definitions and different verification. ReCAAP receives through government focal points and verifies officially; the industry centre receives directly from ships and uses a broader operational definition. Neither is wrong, and the size of the gap for a given water is a useful measure of reporting completeness there.

What is the severity classification actually based on?

A violence factor covering the number of perpetrators, whether they were armed and with what, and how the crew was treated, combined with an economic loss factor covering what was taken. The published methodology is on the site and you should read it before mapping the categories onto your own scheme.

Which states are not in the agreement, and why does it matter?

Two of the most incident-dense archipelagic states in Southeast Asia have historically not acceded, which means incidents in their waters do not flow through the treaty mechanism. Check the current contracting party list on the site, because it changes, and state the resulting coverage gap in any regional product.

Does it cover the Gulf of Guinea or the Horn of Africa?

No. The reporting area is Asia. Incidents elsewhere may be mentioned for context but are not systematically recorded. Use the official government feed, the industry centre and the relevant regional mechanisms for other waters.

Can I republish the incident tables in a commercial product?

Assume not without permission. Free to read is not open licensing. Cite specific reports, quote briefly, derive your own statistics, and if you need redistributable rows use the public-domain government feed as your base layer.

How quickly does the record reflect an incident?

Significant incidents generate immediate alerts and most incidents appear in the following weekly report, which is fast for a verified government-channel product. But early details are provisional and get revised in the monthly and annual consolidations, so treat the first account as indicative.

Is a rise in incidents a rise in risk?

Not necessarily. Counts move with traffic volume, anchorage congestion and focal point reporting activity. Normalise against transits or ship-hours at anchor, check the severity composition rather than the total, and check whether a state's reporting posture changed before you tell anyone risk has increased.

How should I use this alongside the other maritime sources?

Build your machine-readable base on the public-domain official feed, enrich it with ReCAAP's severity and legal classification and follow-up detail for Asian waters, and use the industry record as a third read on completeness. The disagreements between the three are informative and should be preserved rather than reconciled away.

Standards, formats and interoperability

What this source speaks natively, and what it has to be translated into before a partner can consume it. Work that arrives in a recognised format is easier to defend, easier to hand over and easier to automate against:

  • The distinction between piracy under the law of the sea and armed robbery against ships within territorial waters is applied per incident, which is the legal standard the whole domain rests on and which no other open source encodes consistently.
  • The ISC's own severity classification is a published, reproducible scheme and should be preserved verbatim in any store, with derived ladders built on top rather than replacing it.
  • IMO numbers are present in most records and are the correct persistent vessel identifier for reconciliation with registries, port state control data and AIS identity.
  • Incidents map to STIX 2.1 incident and location objects with vessel identity as an identity object; the severity and legal category should be carried as labelled properties rather than flattened into a single severity score.
  • Positions are reported at ship-report precision and should be handled in a standard geodetic frame, with territorial sea and archipelagic baselines available for deriving the jurisdictional context.
  • Reporting flows through designated national focal points under a treaty framework, which is the institutional standard that determines coverage and should be documented alongside any figure you publish.
  • Industry best management practice documents provide the countermeasure taxonomy that recommendations derived from this record should map onto for a shipping audience.

References

Primary documentation and authoritative references for this source. Publishers revise and retire material, so treat the retrieval date as part of the citation and re-check before relying on any of it in a formal product.

  1. ReCAAP Information Sharing Centre — ReCAAP ISC. The centre itself: weekly, monthly, quarterly and annual reports, incident alerts, the contracting party list and the published classification methodology.
  2. International Maritime Organization — IMO. The legal framework distinguishing piracy from armed robbery against ships, plus reporting and investigation guidance that underpins the ISC's categories.
  3. IMO GISIS — IMO. State-reported incident data, useful as a third reading alongside the treaty mechanism and the industry record.
  4. NGA Maritime Safety Information — US National Geospatial-Intelligence Agency. The public-domain, machine-readable incident feed that should be your base layer where licensing and automation matter.
  5. IMB Piracy Reporting Centre — ICC International Maritime Bureau. The industry-side record collected directly from ships; the standard comparison for testing reporting completeness in Asian waters.
  6. Equasis — Equasis. Free ship particulars, ownership and management data – the immediate pivot from the IMO numbers that this source usually provides.
  7. BIMCO — BIMCO. Industry guidance, security clauses and best management practice for affected regions, and the practical output side of any assessment written for a shipping client.
  8. UNODC — United Nations Office on Drugs and Crime. Analysis of the wider maritime crime economy in Asia, including the onward markets for stolen stores, fuel and cargo that the incident record does not follow.
  9. IMO maritime security — IMO. The IMO s maritime security work programme, covering the guidance and reporting framework that the treaty mechanism operates within.

Link integrity: every reference above was verified with a live request when this page was generated. Where a publisher had moved or withdrawn a document, the link was repointed at a preserved copy in the Internet Archive and marked as archived. Anything with no reachable copy anywhere had its link removed rather than left to rot — the source is still credited, it simply cannot be linked.

Put it into practice

The Quantus Intel threat intelligence platform operationalises this source: it preserves the ReCAAP severity and legal categories verbatim, resolves every victim vessel on its IMO number so repeat victimisation becomes visible, and renders Asian incident series against traffic with the non-party coverage gap stated on the product.. Browse the full source catalogue, or follow any tag above into the rest of the library.

Leave a Reply